Security & data

Your data stays in Dubai. Your rules bind every AI agent.

Security and data protection are part of the design: where data is hosted, what an AI may see and do, and what is kept on record.

At a glance

  1. Hosted in Dubai. All customer data is hosted on Microsoft Azure in the UAE North region, in Dubai.

  2. Pseudonymised AI requests. AI models only receive pseudonymised data and never KYC data. The provider stores nothing and trains on nothing.

  3. Permissions before the model. Every data access and every action of an AI agent is checked against its permissions first.

  4. People decide. Money, signatures, AML and HR decisions always stay with people.

  5. Every step on record. An append-only, hash-chained evidence log with an export that can be verified independently.

Hosting

Where your data is hosted

All customer data is hosted in Dubai. Only two services run in the EU, and neither stores customer data.

  • Application server and background jobs

    DubaiLocation: Microsoft Azure UAE North, Dubai

    Protection: Every request and job carries the brokerage it belongs to.

  • Database (PostgreSQL)

    DubaiLocation: Microsoft Azure UAE North, Dubai

    Protection: Row-level security separates every brokerage.

  • File storage

    DubaiLocation: Microsoft Azure UAE North, Dubai

    Protection: File paths carry the brokerage; identity documents sit in an encrypted vault.

  • Encryption keys and secrets

    DubaiLocation: Azure Key Vault with hardware security module, Dubai

    Protection: Central key management; no secrets in code.

  • Backups

    DubaiLocation: Dubai; a second copy in Abu Dhabi once that region opens for us

    Protection: Encrypted; the same residency rules as live data.

  • AI models

    EULocation: Amazon Bedrock, Frankfurt (EU)

    Protection: Pseudonymised input only, zero data retention, no training.

  • System e-mail

    EULocation: Amazon SES, Frankfurt (EU)

    Protection: Send only, nothing stored.

  • Public website

    WebsiteLocation: Vercel

    Protection: Never receives customer data.

Our staging environment has run in Dubai since 28 September 2026. A separate production environment in Dubai follows with the first pilot brokerage. Real customer data is processed only after a legal review of the set-up.

Data flow

How data flows

Customer data stays inside the platform in Dubai. What leaves it is limited to pseudonymised AI requests and outgoing system e-mail.

Your brokerage

Owners, brokers and staff in the browser and the broker app

Microsoft Azure UAE North · Dubai

  • Application and jobs
  • Database
  • Files
  • Keys (HSM)
  • Backups

AI gateway

Checks permissions, pseudonymises, logs every call

EU · Frankfurt

AI model

Amazon Bedrock: pseudonymised input, zero retention, no training

System e-mail

Amazon SES: send only, nothing stored

Public website

Vercel: no customer data. The sign-up form sends directly from the browser to Dubai.

Diagram: simplified data flow

AI governance

How we govern AI

AI agents in Zolia work like members of the team, with clear rules, not like a black box.

  • Permissions before the model

    Every data access and tool call of an AI agent is checked against its permissions. Agents do not inherit the rights of the person who approved them.

  • AI gateway

    KYC data never reaches a model, and confidential data only in pseudonymised form. Only models with zero data retention are used, under a residency policy per brokerage. Every call is logged with purpose, model, region, cost and the responsible person.

  • Autonomy set by the brokerage

    Levels per agent and type of action, with an emergency stop. Money actions are capped; signatures, payouts and AML decisions always stay with people.

  • Quality before release

    An evaluation suite for every AI function, an output check before every AI draft, and defences against prompt injection tested in English and Gulf Arabic.

  • AML by design

    Only the compliance agent can read the AML area, and it has no client channel. Other agents see only “compliance hold”, which prevents tipping-off.

Security controls

Built in and covered by automated tests

  • Tenant isolation

    PostgreSQL row-level security separates every brokerage; files and background jobs carry the brokerage they belong to.

  • Access and identity

    Sign-in with one-time codes and passkeys; permissions are checked for every action, by people and by AI agents.

  • Audit and evidence

    An audit log records every change and stores confidential values only as keyed hashes. Key events go into an append-only, hash-chained evidence log with integrity checks, alarms and an independently verifiable export.

  • Encrypted vaults

    Identity documents sit in an encrypted vault. Third-party credentials of a brokerage, for example DLD or portal access, are stored only encrypted, with no read path for people, the API or exports.

  • Retention and deletion

    Retention classes with deadlines, legal hold and proof of deletion.

  • Secure development

    Automated tests run on every change. Code, dependencies, containers and secrets are scanned, and critical findings block a release.

Data protection

Data protection principles

  • Built for the UAE data protection law (Federal Decree-Law No. 45 of 2021): only the data a feature needs, used for its stated purpose.
  • Zolia staff see a brokerage's data only with that brokerage's time-limited, logged approval. Emergency access is possible only with immediate notice.
  • No AI training on one brokerage's content for other brokerages without opt-in, and never on WhatsApp content.
  • A consent register governs all client communication.

Next steps

What comes next

  • A UAE law firm reviews terms, data processing and data residency before the pilot.
  • An external penetration test before production.
  • ISO 27001 at a later stage.